Description
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.securityfocus.com/bid/108045
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844
Related Vulnerabilities
CVE-2017-16134 Vulnerability in npm package http_static_simple
CVE-2020-4051 Vulnerability in npm package dijit
CVE-2014-0073 Vulnerability in npm package cordova-plugin-inappbrowser
CVE-2022-24772 Vulnerability in npm package node-forge
CVE-2021-23899 Vulnerability in maven package com.mikesamuel:json-sanitizer